Chrome auto-updates in the background, which is exactly why most people never notice how often it has needed to this year. This is the seventh time in 2026 that update has closed a hole attackers were already using.
Two zero-days, five days apart
On September 3, Google fixed CVE-2026-85046, a type confusion bug in V8 that was already under active exploitation. Five days later, on September 8, Google shipped Chrome 153.0.8010.36/.37 to fix a second, unrelated V8 flaw, CVE-2026-87491, an out-of-bounds write that lets an attacker execute code inside the browser sandbox through nothing more than a specially crafted HTML page. Google has confirmed an exploit for it exists in the wild. CISA added CVE-2026-87491 to its Known Exploited Vulnerabilities catalog on September 9, one day after the patch shipped.
The two bugs are unrelated flaws in the same engine, not two stages of one campaign, which is arguably the more concerning detail. It means two separate working exploits against V8 were live at the same time, from presumably different actors, in the same short window.
Why V8 keeps being the target
V8 is the JavaScript and WebAssembly engine underneath Chrome, and by extension underneath every Chromium-based browser: Edge, Brave, Opera, and the embedded browser views inside a large share of desktop applications. A working V8 exploit is not a Chrome problem, it is a browser-engine problem with a blast radius that follows the engine everywhere it is embedded. That breadth is exactly why V8 has now produced seven confirmed zero-days in a single year, more than any other single component in the browser, and why attackers keep investing research effort into finding the next one.
What this means for a European IT estate
Chrome’s auto-update mechanism means most consumer installs patch themselves within a day or two without anyone acting. The risk sits with everything that does not follow that path: locked-down corporate images where updates are staged and tested before rollout, embedded Chromium components inside line-of-business or point-of-sale applications that only get updated when the vendor ships a new release, and any environment where update policies were set once and never revisited. An eight-day gap between a zero-day being weaponised and your endpoints actually receiving the fix is, in 2026, a realistic window for exposure, not a theoretical one.
If your organisation manages Chrome or Chromium-based software through a staged rollout, or you are not confident every device, including the ones running an embedded browser inside another application, is current, contact Excello Digital. We help European IT teams build a patch cadence that keeps pace with a browser that is now shipping emergency fixes roughly once a month.
